Skip to content

CertiStack editions and repository boundary

This repository is the public, open source CertiStack Community Edition. It is the authoritative source for the community CLI, reusable validation engine, test-plan schema, signed JSON evidence and its verification, and public documentation.

Community Edition

Community Edition is free, open source software under the GNU Affero General Public License v3.0 (AGPLv3) — see LICENSE and LICENSING-FAQ.md. There is no capacity cap and no restriction on commercial use; AGPLv3's only material condition is that a modified version, run as a network service, must offer its users the modified source. It runs from an operator-managed controller host and keeps test plans and reports there. A Community run bootstraps a temporary PVE node worker for node-local backup mapping and sandbox operations; it does not install the full product on PVE.

Community support is provided through public issues and discussions on a best-effort basis. It does not include an SLA, managed recovery services, or a compliance certification.

CertiStack Enterprise Edition

The Enterprise Edition is a separately packaged commercial product for managed service providers. Its currently documented package owns the persistent certistackd service, installed on each Proxmox VE node it validates (a node-local root service, one per node), its embedded management dashboard, HTTP API, HTML/PDF compliance-binder rendering, outbound notifications and webhooks, entitlement enforcement, protected-asset metering, tenant separation, and partner operations. A distributed signed node connector, managed scheduling, fleet orchestration, and integrations are support-boundary capabilities: they may be offered only when their implementation and retained release evidence are documented. None of them ships in the current package: there is no central controller that drives several nodes' daemons. Availability and scope are defined in the applicable order form and product documentation; they are not promised by this repository.

Commercial code, customer configuration, pricing, partner operations, and support commitments are deliberately kept outside this public repository.

Security boundary

The Community source tree must never contain an API token, signing key, report from a real environment, customer data, or private Enterprise source.

The Community license governs permitted use; it is not an execution-time security boundary. Authorization for commercial services must be enforced by the private product.

Maintaining the split

When changing this repository:

  • Keep public docs factual and edition-neutral; do not publish internal pricing, sales targets, partner playbooks, or unannounced roadmap commitments.
  • Put commercial-only source and release automation in the private Enterprise product repository or build pipeline. Report rendering (HTML/PDF), outbound notifications, scheduling, multi-tenant features, and entitlement code are commercial-only by definition; the Community engine emits and verifies signed JSON and nothing more.
  • Treat the LICENSE in the Community source distribution as the authoritative public license. Have counsel review any commercial order form, EULA, or changes to license terms before publication.